Probe of leaked U.S. NSA hacking tools examines operative’s ‘mistake’
reuters.com
reuters.com
Then the paranoid part of me wonders if that's the plan. Then the skeptical part of me says, "Occam's Razor". Then I remember that I'm insignificant in relation to these issues and I have some tea.
As far as I can tell, incompetence by far seems to be most likely here. I don't think NSA would wittingly give up so many nice zero-days to their first or second most powerful rival agency.
The person who uploaded them there did government security before joining comcast, so it doesn't surprise me even for a second that this was a mistake. Though, the repo also had updates after his employment there ended.
I imagine this sort of thing is pretty common.
I feel like NSA might be able to make a stronger case for themselves if they were at least able to show they could do one of the most basic and fundamental things they're supposed to do be doing.
Oh, it starts out great when there are clearly defined sides and reasonable evidence of loyalty to a particular party. Real victories and losses can be defined. But it always degrades to this sort of thing after a bit of time and growth in numbers of players, and no one wins or loses. There is just confusion, perhaps even for those at the top of the chain.
1. They were probably relying on those exploits quite a bit and had frequent success with them, in which case totally burning them would have directly harmed operational capacity.
2. They appear to be huge fans of piggybacking off of other intelligence agencies' footholds and data ("fourth-party collection").
http://www.theverge.com/2015/1/17/7629721/nsa-is-pwning-ever...
>Fourth party collection appears so successful that agents of the NSA and GCHQ have cracked jokes about it in top secret slide decks. In an NSA presentation titled "fourth party opportunities," the first slide references Daniel Day-Lewis' infamous "I drink your milkshake"
Another intelligence agency acquiring these exploits would give them additional "fourth-party opportunities". As long as the US government's systems were protected against the exploits (were they? no idea), that could mean keeping them secret still meant more pros than cons for their goals. It could give them more intel, and maybe give additional insight into the other nation's goals and interest by who they're targeting.
Pure speculation on my part, though. The real reason could just be regular old incompetence, and/or internal cover-up of the tool leakage.
Furthermore, they can't really keep using them after exposure for the same reason the Russians didn't start using them: everyone who knows about them can watch for them being exploited and so gain useful intelligence on their rivals.
How do we know they don't? Or at least, some of their exploits.
Also, that's not necessarily the only conclusion. This leak could have have been more harmful than no leak, yet thought to be less harmful than publicly burning every exploit.
>Furthermore, they can't really keep using them after exposure for the same reason the Russians didn't start using them: everyone who knows about them can watch for them being exploited and so gain useful intelligence on their rivals.
True, but they could possibly change them in a way to make them less detectable.
The Russians could have done the same, but maybe their reason for believing it'd be helpful for fourth-party collection is that they already had access to some of Russian intelligence's communications and compromised hosts, devices, and networks.
Anything could be possible here, though. We're all speculating pretty blindly.
The principal rival in the short term for any department whether of government or inside a company is other departments not the corresponding department in another company. In fact it is plausible to think that at least some of the people within agencies like the NSA have more in common and a substantial degree of fellow feeling with their nominal rivals in, for instance, Russia than they have with other US agencies.
I'm not saying that I personally would reach the same conclusion, just that the situation is more complex than Reuters makes it out to be.
[0]https://medium.com/@thegrugq/mind-games-international-champi...
"One reason for suspecting government instead of criminal involvement, officials said, is that the hackers revealed the NSA tools rather than immediately selling them."
...is the sort of reasoning a kid might put forth.
Nothing like keeping alive the narrative for justification of war with Russia while concurrently obfuscating the flawed and open, contractor policy embraced by US agencies.
b) Never attribute to ignorance what is properly and accurately attributed to malice.
Yes, I've seen it happen. And yes, I've seen it in person, not only on the net. No, I don't think it is the case here, because evidence points other way - not because of this stupid canned thought.